LOW
0215AndrewFeng
CVE published 2026-09-20
CVE-2026-94046
A weakness in 0215AndrewFeng ACE-MCP up to 4.10.8 allows for path traversal via the get_file_snippet function in getFileSnippet.ts. This issue can be exploited remotely. The project has been informed but has not yet responded. The vulnerability is caused by the isPathInsideProjectRoot guard being insufficient, as it only blocks filePath escaping the attacker-chosen projectRootPath, but not the root itself [truncated]